<?php
require_once( './includes/WebStart.php' );


if( $wgUser->isLoggedIn() &&  is_numeric($_POST[id_file]) && !is_null($_POST[id_file]) && $_POST[comment] !== '' ) {
  global $IP, $wgScript, $wgLang;
  
  
  $id_user = mysql_real_escape_string($wgUser->getId());
  $id_file = mysql_real_escape_string($_POST[id_file]);
  $datenow = date("Y-m-d H:i:s", time());
  
  $comment = strip_tags(mysql_real_escape_string($_POST[comment]));
  $comment = str_replace(wfMsg('write_here_your_comment'), '',$comment);
  $lang =  $wgLang->getCode();
  
  //var_dump(strlen($comment));
  //die();
  
  if ( strlen($comment) > 0){
      $dbw =& wfGetDB( DB_MASTER );
      $dbw->begin();   
      $sql = "INSERT INTO ss_file_comments (id_user, id_file, date, comment, lang)
                VALUES ('$id_user' , '$id_file', '$datenow', '$comment' ,'$lang')";
           
      $dbw->query( $sql );
      $dbw->commit();
  }
} 


header('Location: '.$_SERVER['HTTP_REFERER']);